Pinging all the experts here -->Zone Alarm anti-spyware just found 2 trojans that Avast/Ad-Aware/Spybot S&D didn't

Pinging all the experts here -->Zone Alarm anti-spyware just found 2 trojans that Avast/Ad-Aware/Spybot S&D didn't

Secure Home | Search | About
 Anti-Virus Software    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Pinging all the experts here -->Zone Alarm anti-spyware just found 2 trojans that Avast/Ad-Aware/Spybot S&D didn't bettersurfing 08-01-2006
Posted by David H. Lipman on August 1, 2006, 6:38 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


| Will do. I just ran SuperAntispyware and asquared and so far all is
| clean.
| I'm going to run my trial version of Spy Sweeper (and use the requisite
| 99% of CPU power required by Spy Sweeper - LOL).
|
| The question is - is it better to run Anti-spyware programs to catch
| Trojans or AV programs? In addition, should I shut down my Avast shields
| when running anti-spyware programs and disconnect from the net if I'm not
| running them in safe mode?
|

If you get infected -- both !

Prevention is always better than cure.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by on August 3, 2006, 1:45 am
If you were  Registered and logged in, you could reply and use other advanced thread options

>
>
>| Will do. I just ran SuperAntispyware and asquared and so far all is
>| clean.
>| I'm going to run my trial version of Spy Sweeper (and use the
>| requisite 99% of CPU power required by Spy Sweeper - LOL).
>|
>| The question is - is it better to run Anti-spyware programs to catch
>| Trojans or AV programs? In addition, should I shut down my Avast
>| shields when running anti-spyware programs and disconnect from the
>| net if I'm not running them in safe mode?
>|
>
> If you get infected -- both !
>
> Prevention is always better than cure.
>

Very interesting - these people in the Zone Alarm forums state the ZA
Anti-Spyware found the same two trojans and there seems to be no info
about them. Could they be false positives? I'll try to follow up if
and when ZA ever responds. For a highly rated product, ZA moderators
sure take their sweet time to respond (and many posts are never answered
there):


http://forum.zonelabs.org/zonelabs/board/mes
sage?board.id=Antivirus&message.id=13092


Win32.YOK.SuperSearch
Park
New Member
Registered: 12-09-2005




Situation: During my DAILY spyware scan, on 8/1/2006, ZoneAlarm detected
Win32.YOK.SuperSearch

which ZA said was a high risk trojan.

Questions:
1) Am I now to assume that, during the many hours that I was online
between my daily scans, a program which "enables user access to your
entire computer and everything on it" could have **bleep**ed very
important info from my computer &/or made other major changes to my
system?
2) Where is any information that might aid me in finding out when and
exactly how I acquired this spyware?
3) Why does Win32.YOK.SuperSearch not appear on the list in "SmartDefense
Research Center/ Spyware Information" at
http://smartdefense.zonelabs.com/tmpl/SpywareArticle?
action=letterSearch&SPY_LETTER=w?
4) Why am I unable to find any detailed info at ZA about this program or
any info at all about it at any other site (such as Spysweeper or
Symantec/Norton)?
5) Last, but hardly least, how can I detect such nasties BEFORE they have
a chance to mess with my computer?

Thanks,
Park






http://forum.zonelabs.org/zonelabs/board/message?
board.id=Antivirus&message.id=13100


ZA Pro scans and picks this up:
RegistryKey: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\.cha

*** Backdoor.Win32.mIRC.based ***

Status "Quarantined" for now.

The following great programs do not detect this:
* Spybot Search and Destroy
* Ad-Aware SE
* AVG
* ewido

All four are up to date with current sigs.

Why does ZAPro and not the others??

Anyone care to elaborate please and thanks?
Operating System: Windows XP Home
Product Name: ZoneAlarm Pro
Software Version: 6.5

by RKnee



Posted by on August 4, 2006, 3:03 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
It appears (from rechecking the Zone Alarm url's) that the
yok.supersearch is not a trojan but adware and may be legit (but my
computer had none of the yok.* files listed in the Zone Alarm forum other
than the registry setting that Zone Alarm removed).

The Backdoor.Win32.mIRC.based trojan was a false positive that Zone Alarm
corrected with a future definition update.

Just great - Zone Alarm made me waste about 4 hours checking the net and
rerunning several anti-spyware programs plus an Avast bootscan and normal
start-up virus scan.

I almost did a Multi-AV scan, too!



>
>>
>>
>>| Will do. I just ran SuperAntispyware and asquared and so far all is
>>| clean.
>>| I'm going to run my trial version of Spy Sweeper (and use the
>>| requisite 99% of CPU power required by Spy Sweeper - LOL).
>>|
>>| The question is - is it better to run Anti-spyware programs to catch
>>| Trojans or AV programs? In addition, should I shut down my Avast
>>| shields when running anti-spyware programs and disconnect from the
>>| net if I'm not running them in safe mode?
>>|
>>
>> If you get infected -- both !
>>
>> Prevention is always better than cure.
>>
>
> Very interesting - these people in the Zone Alarm forums state the ZA
> Anti-Spyware found the same two trojans and there seems to be no info
> about them. Could they be false positives? I'll try to follow up if
> and when ZA ever responds. For a highly rated product, ZA moderators
> sure take their sweet time to respond (and many posts are never
> answered there):
>
>
> http://forum.zonelabs.org/zonelabs/board/mes
> sage?board.id=Antivirus&message.id=13092
>
>
> Win32.YOK.SuperSearch
> Park
> New Member
> Registered: 12-09-2005
>
>
>
>
> Situation: During my DAILY spyware scan, on 8/1/2006, ZoneAlarm
> detected
> Win32.YOK.SuperSearch
>
> which ZA said was a high risk trojan.
>
> Questions:
> 1) Am I now to assume that, during the many hours that I was online
> between my daily scans, a program which "enables user access to your
> entire computer and everything on it" could have **bleep**ed very
> important info from my computer &/or made other major changes to my
> system?
> 2) Where is any information that might aid me in finding out when and
> exactly how I acquired this spyware?
> 3) Why does Win32.YOK.SuperSearch not appear on the list in
> "SmartDefense Research Center/ Spyware Information" at
> http://smartdefense.zonelabs.com/tmpl/SpywareArticle?
> action=letterSearch&SPY_LETTER=w?
> 4) Why am I unable to find any detailed info at ZA about this program
> or any info at all about it at any other site (such as Spysweeper or
> Symantec/Norton)?
> 5) Last, but hardly least, how can I detect such nasties BEFORE they
> have a chance to mess with my computer?
>
> Thanks,
> Park
>
>
>
>
>
>
> http://forum.zonelabs.org/zonelabs/board/message?
> board.id=Antivirus&message.id=13100
>
>
> ZA Pro scans and picks this up:
> RegistryKey: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\.cha
>
> *** Backdoor.Win32.mIRC.based ***
>
> Status "Quarantined" for now.
>
> The following great programs do not detect this:
> * Spybot Search and Destroy
> * Ad-Aware SE
> * AVG
> * ewido
>
> All four are up to date with current sigs.
>
> Why does ZAPro and not the others??
>
> Anyone care to elaborate please and thanks?
> Operating System: Windows XP Home
> Product Name: ZoneAlarm Pro
> Software Version: 6.5
>
> by RKnee
>
>
>


Posted by David H. Lipman on August 4, 2006, 7:20 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| It appears (from rechecking the Zone Alarm url's) that the
| yok.supersearch is not a trojan but adware and may be legit (but my
| computer had none of the yok.* files listed in the Zone Alarm forum other
| than the registry setting that Zone Alarm removed).
|
| The Backdoor.Win32.mIRC.based trojan was a false positive that Zone Alarm
| corrected with a future definition update.
|
| Just great - Zone Alarm made me waste about 4 hours checking the net and
| rerunning several anti-spyware programs plus an Avast bootscan and normal
| start-up virus scan.
|
| I almost did a Multi-AV scan, too!


Thanx for updating the thread.

Good Luck !

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by on August 5, 2006, 4:30 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

>
>| It appears (from rechecking the Zone Alarm url's) that the
>| yok.supersearch is not a trojan but adware and may be legit (but my
>| computer had none of the yok.* files listed in the Zone Alarm forum
>| other than the registry setting that Zone Alarm removed).
>|
>| The Backdoor.Win32.mIRC.based trojan was a false positive that Zone
>| Alarm corrected with a future definition update.
>|
>| Just great - Zone Alarm made me waste about 4 hours checking the net
>| and rerunning several anti-spyware programs plus an Avast bootscan
>| and normal start-up virus scan.
>|
>| I almost did a Multi-AV scan, too!
>
>
> Thanx for updating the thread.
>
> Good Luck !
>

Actually, I do it not only for the benefit of future surfers, but for
myself, too. In the future, I'll be able to do Google newsgroup searches
and see the ZA threads.

I was amazed at how little there was on the net and in the newsgroups
regarding these two bits of spyware.

All the AV and anti-spyware companies (especially the one I use - Avast)
give precious little info on trojans and spyware. Sure they may block it
at the point of impact, but it would be nice to see what files or registry
strings they plant, so we could do a file or reg search just to be sure.

Similar ThreadsPosted
Zone Alarm Experts November 4, 2005, 7:25 pm
SL7.tmp found by Zone Alarm July 28, 2007, 1:33 pm
Zone Alarm install error "ssleay32.dll" not found December 12, 2005, 4:38 pm
Plenty of trojans found in Sun Java cache July 2, 2005, 3:42 pm
Zone Alarm V Nod 32???? December 9, 2005, 7:15 pm
Zone Alarm July 11, 2006, 3:09 am
Zone Alarm AV August 3, 2006, 5:19 pm
Zone Alarm/Messenger???? August 21, 2005, 9:44 pm
Zone Alarm 6 Suite September 9, 2005, 9:39 pm
eTrust Vs Zone Alarm December 7, 2005, 4:04 pm

The site map in XML format XML site map

Contact Us | Privacy Policy